CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,458 vulnerabilities with CWE-94
CVE-2026-39087 CRITICAL
ntfy < 2.22.0 - Server-Side Request Forgery
CVSS 9.8
CVE-2026-39440 CRITICAL
WordPress FunnelFormsPro plugin <= 3.8.1 - Remote Code Execution (RCE) vulnerability
CVSS 9.9
CVE-2026-3960 CRITICAL
Remote Code Execution in h2oai/h2o-3
CVSS 9.8
CVE-2026-41229 CRITICAL
Froxlor <2.3.6 MysqlServer API - PHP Code Injection
CVSS 9.1
CVE-2026-41196 CRITICAL
Luanti 5.0.0-5.15.1 LuaJIT Mod Sandbox - Sandbox Escape
CVSS 10.0
CVE-2026-41134 HIGH
Kiota: Code Generation Literal Injection
CVSS 7.8
CVE-2026-33608 HIGH
Incomplete domain name sanitization during
CVSS 7.4
CVE-2026-40911 CRITICAL
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
CVSS 10.0
CVE-2026-6745 LOW
Bagisto Custom Scripts cross site scripting
CVSS 3.5
CVE-2026-40602 MEDIUM
hass-cli: Handling of user-supplied Jinja2 templates
CVSS 5.6
CVE-2026-6743 LOW
WebSystems WebTOTUM Calendar cross site scripting
CVSS 3.5
CVE-2026-31018 HIGH
Dolibarr ERP & CRM <=22.0.4 - Code Injection
CVSS 8.8
CVE-2026-32613 CRITICAL
Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling
CVSS 9.9
CVE-2026-6652 MEDIUM
Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection
CVSS 4.7
CVE-2026-6651 LOW
erponline.xyz ERP Online Inventory Edit Item cross site scripting
CVSS 2.4
CVE-2026-39918 CRITICAL
Vvveb < 1.0.8.1 Code Injection via Installation Endpoint
CVSS 9.8
CVE-2026-5760 CRITICAL
SGLang - Remote Code Execution via Malicious Tokenizer Chat Template
CVSS 9.8
CVE-2026-6648 LOW
Qibo CMS Internal Message cross site scripting
CVSS 3.5
CVE-2026-6633 LOW
Yifang CMS Extended Management L_rbac_admin.php store cross site scripting
CVSS 3.5
CVE-2026-6624 LOW
BichitroGan ISP Billing Software Pool List add cross site scripting
CVSS 2.4
CVE-2026-6623 LOW
BichitroGan ISP Billing Software Profile users-view cross site scripting
CVSS 2.4
CVE-2026-6622 LOW
BichitroGan ISP Billing Software Customer edit cross site scripting
CVSS 2.4
CVE-2026-6621 HIGH
1024bit extend-deep index.js prototype pollution
CVSS 7.3
CVE-2026-6619 LOW
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
CVSS 3.5
CVE-2026-41282 MEDIUM
ProjectDiscovery Nuclei <3.8.0 - DSL Injection
CVSS 4.0
Details
Vulnerabilities 6,458
Exploit Likelihood Medium